Authors
Jaehong Park, Ravi Sandhu
Publication date
2004/2/1
Journal
ACM transactions on information and system security (TISSEC)
Volume
7
Issue
1
Pages
128-174
Publisher
ACM
Description
In this paper, we introduce the family of UCONABC models for usage control (UCON), which integrate Authorizations (A), oBligations (B), and Conditions (C). We call these core models because they address the essence of UCON, leaving administration, delegation, and other important but second-order issues for later work. The term usage control is a generalization of access control to cover authorizations, obligations, conditions, continuity (ongoing controls), and mutability. Traditionally, access control has dealt only with authorization decisions on users' access to target resources. Obligations are requirements that have to be fulfilled by obligation subjects for allowing access. Conditions are subject and object independent environmental or system requirements that have to be satisfied for access. In today's highly dynamic, distributed environment, obligations and conditions are also crucial decision factors for richer …
Total citations
200320042005200620072008200920102011201220132014201520162017201820192020202120222023202447315974103120109139106958972766961525035504721
Scholar articles
J Park, R Sandhu - ACM transactions on information and system security …, 2004
P Jaehong, S Ravi - ACM Trans. Inf. Syst. Secur, 2004